
httpx
Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fil-C: completely compatible memory safety for C and C++

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Inject code into running Python processes

A wrapper around grep, to help you grep for things

Automatic SSTI detection tool with interactive interface

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

The repo contains a series of challenges for learning Frida for Android Exploitation.

LLM powered fuzzing via OSS-Fuzz.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Differential testing framework for HTTP implementations